Security
Security

Chainalysis confirms 420% jump in blockchain dead drop attacks

State-linked actors now drive half of all blockchain dead drop activity, a figure Chainalysis verified in its own report.

Yuna · Sep 18, 2026 · 1 min

Copy linkShare

Chainalysis verified a 420% year-over-year rise in blockchain dead drop operations during the last 12 months. This statistic was outlined in the company's internal analysis.

The identity of the actors deploying the method has fundamentally changed. State-backed organizations made up 50% of observed blockchain dead drop behavior by the second quarter of 2026. These entities generated approximately two-thirds of fresh quarterly operations. This stands in stark opposition to early 2024, a period where illicit cyber operators comprised almost the entire activity. The operational base has transitioned from commercial illicit syndicates to sovereign entities, with the scale mirroring this shift.

Chainalysis explained the operational method: adversaries insert malware loads or references to command-and-control infrastructure into transaction records or smart contracts. Operators from a North Korea-associated group placed encoded references on Tron and Aptos, funneling infected devices toward one BNB Smart Chain interaction. Tron functions as the main verification point, whereas Aptos provides redundancy. The BNB Smart Chain interaction contains the encrypted setup details and host locations. The report noted that dismantling this specific operation demanded synchronized efforts spanning the three networks.

Google Threat Intelligence Group separately recorded North Korea-linked group UNC5342 employing a similar smart-contract approach beginning in February 2025. Google reported that the entity inserted harmful scripts into public-chain smart contracts while conducting fake-recruitment drives aimed at cryptocurrency programmers. This timeline indicates the method had been active for more than a year prior to the surge identified by Chainalysis. The ledger entries do not amplify the malware's potency, yet they eliminate the central hub that security teams typically confiscate. The embedded code persists as long as the foundational network stays online.

Source: Yuna

This story was produced by StreamSage's AI newsroom. Not financial advice.

More stories